Skip to Content

Issues with Staying on IdentityServer4

 IdentityServer4 gravestone marked "RIP December 2022"
  • End of life: IdentityServer4 is no longer maintained or patched, no security fixes, no bug fixes, no support. It was last updated over 3 years ago 
  • .NET incompatibility: targets only unsupported versions of .NET
  • Compliance risks: without ongoing updates, can arise from using IdentityServer4 , potentially putting your organisation at risk with auditors
  • Growing attack surface: identity is a top target for attackers, and having your digital front door not maintained opens up a whole pile of risk for your applications

Start Your Upgrade Journey Now

See how Nailor moved to a fully secure and supported platform today.

Read Nailor Case Study

Reasons Why You Haven't Upgraded Yet

Security risk guage showing high risk for IdentityServer4
  • IdentityServer4 keeps on working, so why change it
  • IdentityServer4 was free, but now I have to pay for a commercial license
  • Upgrading to Duende IdentityServer is a risk, I could break this critical service
  • I have a limited budget, developers are focused on adding value to the core business, and there is no time to do the upgrade
  • Perhaps you never realised that IdentityServer4 was no longer supported

IdentityServer4 will continue to work, but as it's not actively maintained, and neither is the Microsoft platform it runs on, the risk over time is that serious security vulnerabilities may be discovered. Since IdentityServer4 protects your applications and APIs, this means they become vulnerable to these vulnerabilities. Doing nothing is a risk.

It's now not free, but what this means is the software you are relying on is now maintained by a much wider team, giving you confidence that it will continue to protect your applications and APIs for many years to come.

The framework promotes best practices, including key rotation, which was previously a commercial addition to the free, open-source software. Helping you stay up to date with industry best practices.

Good News

Rock Solid Knowledge has been an IdentityServer partner for over 10 years. During this time, it has built, maintained, upgraded and delivered many value-added components to 100s of IdentityServer4 and Duende IdentityServer solutions. So why not let us unblock that upgrade and move you to a fully supported platform?

Let us solve the migration complexity and resource constraint issues. If that's not enough, all upgrades come with a free six-month Duende Enterprise license, saving you up to 10,000 USD on your annual license. With most upgrades costing less than 10,000 that means you get an updated solution for the cost of a regular yearly license.

More Good News

Once upgraded, you don't want to ever be in this situation again. Rock Solid Knowledge will maintain the solution for a fixed annual cost via our Production Support Plus offering. We will apply any security patches and at least four maintenance updates during the year to your solution. Allowing your developers to focus on your core business while keeping you safe and secure.

Arrange a call with one of our experts who will discuss the upgrade process and provide you with a no obligation, fully costed upgrade.

Start Your Upgrade Journey Now

Move to a fully secure and supported platform today.

By submitting this form you are confirming the use of the data you supply in accordance with our privacy policy.